Home > Today’s Crypto News
bitcoin
bitcoin

$107167.915651 USD

-1.23%

ethereum
ethereum

$2484.735224 USD

-0.65%

tether
tether

$1.000551 USD

0.03%

xrp
xrp

$2.227485 USD

1.25%

bnb
bnb

$657.234657 USD

0.38%

solana
solana

$153.359085 USD

0.76%

usd-coin
usd-coin

$1.000234 USD

0.03%

tron
tron

$0.279694 USD

1.12%

dogecoin
dogecoin

$0.164283 USD

-2.04%

cardano
cardano

$0.566559 USD

-0.46%

hyperliquid
hyperliquid

$39.355826 USD

-3.77%

bitcoin-cash
bitcoin-cash

$520.939018 USD

3.97%

sui
sui

$2.773602 USD

-2.77%

chainlink
chainlink

$13.247285 USD

-2.04%

unus-sed-leo
unus-sed-leo

$9.098882 USD

-0.71%

Oracle Manipulation

Oracle manipulation, or oracle price manipulation, is an exploit most common in the DeFi space where an oracle smart contract is manipulated by attackers, which leads to system failure, theft and other damages. DeFi networks are reported to have lost over $33 million due to price oracle manipulation in 2020 alone.

Oracles are third-party service providers that supply blockchains with external or real-world data such as price feeds, weather information, statistics, etc. Price feeds are by far the most exploited oracle data since they allow attackers to steal millions of funds from DeFi platforms. 

Generally, there are two ways an oracle can gather price information. One is to seamlessly siphon price data from centralized exchanges via APIs. On the other hand, oracles can also do the calculations themselves by consulting decentralized exchanges (DEXs). Both methods have their own sets of advantages and disadvantages, as well as ways of being manipulated.

In the Harvest Finance hack, the culprit was able to penetrate its pools through a flash loan using a form of oracle manipulation. Basically, the hacker reduced the value of USDC within the Curve pool via a trade. Then, the perpetrator got into the Harvest pool at the deflated price, brought USDC back to its initial price reversing his trade, then exited the pool at a much higher price.